If your business runs on Microsoft 365 — email, files, calendars, maybe even accounting access — then a single stolen password isn’t a minor inconvenience. It’s a master key. That’s exactly why identity has become the most targeted layer in small business attacks, and why most businesses have nothing watching it.

Key Takeaways

  • ITDR (Identity Threat Detection & Response) monitors sign-ins and account behavior across Microsoft 365 and Active Directory for signs of compromise.
  • Credential theft often triggers zero antivirus or firewall alerts, because no malware is involved — just a login.
  • A common and costly tactic, malicious mailbox forwarding rules, can sit undetected for months.
  • ITDR is one of the three layers in Humacentric Guardian, alongside Managed EDR and Security Awareness Training.

Your Firewall Doesn’t See a Stolen Password

Most small business security spending goes toward protecting devices and networks — firewalls, antivirus, endpoint tools. All of that is necessary, and none of it has any visibility into what happens when an attacker simply logs in with a real employee’s real credentials, obtained through a phishing email or a reused password from some other breach.

From the system’s perspective, that’s not an attack. It’s just a login. Nothing gets flagged unless something is specifically watching identity behavior.

What Identity Threat Detection Actually Watches For

  • Impossible travel — a login from Florida followed by one from another country twenty minutes later
  • Suspicious mailbox rules — a rule quietly forwarding every email mentioning “invoice” or “wire” to an outside address, a top tactic in business email compromise
  • Privilege escalation — a standard user account suddenly granted admin rights
  • Abnormal sign-in patterns — unusual times, unusual devices, unusual application access

Managed ITDR watches for these patterns across Microsoft 365 and Active Directory around the clock, and coordinates a fast lockout and credential reset the moment something looks wrong — instead of someone noticing three weeks later when a client calls asking why their invoice went to a different bank account.

Why This Is Especially Relevant for Microsoft 365 Shops

Most small businesses have consolidated nearly everything into Microsoft 365: email, file storage, calendars, Teams chats, sometimes even connected accounting platforms. That consolidation is genuinely useful — it’s also exactly why one compromised login is now worth more to an attacker than it used to be. A single account can expose years of email history, financial documents, and client communications at once.

ITDR Doesn’t Replace MFA. It Backs It Up.

Multi-factor authentication is table stakes at this point, and if you don’t have it enforced everywhere, that’s the first fix — before anything else on this list. But MFA fatigue attacks (repeatedly prompting a user until they approve out of frustration) and session token theft can still get around it. ITDR is what catches the account behavior after an attacker gets past that first door.

FAQ

What if we don’t use Microsoft 365?

Managed ITDR as offered today is built around Microsoft 365 and Active Directory. If you’re on a different platform, we’ll tell you honestly during your risk assessment whether it’s a fit.

Does ITDR require us to change how employees log in?

No. It runs in the background monitoring sign-in and account activity — there’s no change to the employee experience unless something suspicious is detected.

Is ITDR sold on its own?

It’s available as an add-on to Guardian Essentials, but it’s included by default in Guardian Complete, which is how most clients run it.

Curious whether your Microsoft 365 environment already shows warning signs? Book a free risk assessment and find out.